Data Storage Device Secure Key Management via Manager Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage devices with encryption technologies are cumbersome for technically unskilled users to set up and manage, leading to insecure storage of keys and passwords, resulting in underutilization and exposure of confidential data.

Innovation Solution

A data storage device with a cryptography engine and access controller that uses a cryptographic key to decrypt data, allowing authorized devices to access encrypted content by generating configuration data based on key data exchanged between a manager device and the data storage device, ensuring secure access and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to secure data storage, then data security is improved, but setup and management becomes cumbersome and complicated

Engineering Contradiction:
Improvedata securityVSAvoidsetup and management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a manager device as an intermediary between the host computer system and the data storage device. This manager device handles the complex cryptographic operations, key management, and authorization processes, shielding the user from technical complexity while maintaining strong encryption security. The manager device communicates with both the host and storage device, mediating authentication and data access without requiring the user to directly manage cryptographic keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If passwords and keys are stored for encryption access, then data access is enabled, but security is compromised due to insecure storage

Engineering Contradiction:
Improvedata accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the sensitive cryptographic keys and passwords from the data storage device itself and stores them securely in a separate manager device. This separation ensures that even if the storage device is compromised, the keys remain protected. The manager device is specifically designed to securely hold cryptographic material and perform authentication operations without exposing keys to potential attackers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The manager device performs self-service by automatically managing cryptographic operations, including key generation, storage, and usage. It handles authentication challenges and responses without requiring manual intervention, thereby maintaining security while enabling convenient access. The system uses challenge-response protocols where the manager device autonomously verifies credentials and manages session tokens.

Inventive Principle:
Principle #25Self-service

3Reliability

If complex authentication protocols are implemented, then security is improved, but user experience deteriorates due to technical complexity

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The manager device serves as an intermediary that handles complex authentication protocols between the host and storage device. It manages cryptographic challenges, responses, and session tokens, presenting a simplified interface to users while maintaining robust security. The host system only needs to interact with the manager device through simple authentication commands, without needing to understand underlying cryptographic complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12118103B2Certificates in data storage devices
Publication Date: 2024.10.15 SANDISK TECHNOLOGIES LLC
  • US12118103B2 patent drawing
  • US12118103B2 patent drawing
  • US12118103B2 patent drawing

AI summary

Disclosed herein is a data storage device. A data port transmits data between a host computer system and the data storage device. A non-volatile storage medium stores encrypted user content data and a cryptography engine connected between the data port and the storage medium uses a cryptographic key to decrypt the encrypted user content data. The access controller generates an authorization request for a manager device. The authorization request comprises a certificate. The certificate comprising key data. In response to receiving the key data in a response to the authorization request generated by the manager device, the access controller generates configuration data based on the key data to register the device to be authorized as an authorized device.